01. Introduction & Scope
Welcome to Kira Bot. We are committed to safeguarding the privacy and security of Discord users, server administrators, and visitors to our official web dashboard.
This Privacy Policy sets forth the principles governing how Kira Bot (Discord Application ID: 1518174702533873764, hereinafter referred to as "Kira", "we", "us", or "our") collects, processes, stores, and protects personal information and Discord guild metadata when you invite Kira Bot to your Discord server or interact with our web platform.
02. Information We Collect
When Kira Bot is added to a server or when a user logs in via Discord OAuth2, the following technical and profile data points may be collected and processed:
| Data Category | Specific Items | Primary Purpose |
|---|---|---|
| User Identity | Discord User ID, username, discriminator/display name, avatar hash | Profile identification, leveling/XP tracking, moderation sanctions, and command attribution |
| Guild / Server Data | Guild ID, server name, channel IDs, role IDs, guild icon hash | Per-server configuration, automated roles, anti-nuke rules, and ticket channel routing |
| Web OAuth2 Data | Discord User ID, user guilds list, avatar | Authenticating access to the Kira Web Dashboard (/dashboard) and managing bot settings |
| Voice State Data | Current voice channel ID, mute/deaf status | High-fidelity music streaming, DJ controls, and Join-to-Create voice channels |
| Support Submissions | Bug reports, feature suggestions, ticket transcripts | Resolving user issues, diagnosing bot errors, and improving platform stability |
No Passwords or Financial Details: Authentication is handled exclusively through Discord's official OAuth2 service. Kira Bot never requests, receives, or stores user passwords or payment card details.
03. Message Content Intent Policy
Kira Bot utilizes the Discord Message Content Privileged Intent strictly for real-time automated server operations. Kira Bot does not maintain a perpetual archive of public or private chat logs.
Message text is evaluated transiently in server memory for the following authorized operations only:
- Prefix Command Execution: Detecting traditional prefix triggers (e.g.
!play,!ban,!help,!rank) and running the requested command. - AutoMod & Safety Filters: Instantaneous inspection for discord invite spam, phishing URLs, malicious file attachments, excessive caps, and custom server blacklisted words.
- Anti-Raid Honeypot System: Detecting automated raid bots that trigger configured trap channels and executing immediate defensive bans or timeouts.
- AFK & Mentions: Detecting mentions of users who have activated AFK status and providing automated notification replies.
- Counting & Mini-Games: Validating consecutive numbers in designated counting channels.
- Support Ticket Transcripts: When server administrators close a support ticket, a transcript of that specific ticket channel is generated only upon explicit moderator request and delivered to the server's designated log channel.
04. How We Use Collected Data
We process collected information solely for legitimate operational purposes:
- To operate and maintain Kira Bot's 437+ commands across music, moderation, economy, leveling, and AI assistance.
- To enable server administrators to customize welcome greetings, ticket systems, reaction roles, and automated moderation rules via our web dashboard.
- To protect servers against unauthorized raids, mass kicks, bot nukes, and rogue administrator compromises via our Anti-Nuke engine.
- To provide customer support and respond to user-submitted bug reports and feature requests.
- To detect and prevent technical abuse, spam, rate-limit bypassing, or unauthorized access to our API.
05. Zero Sale or Monetization of User Data
We will only disclose stored data under the following extremely limited conditions:
- To comply with a valid, legally enforceable court order or subpoena from a competent law enforcement authority.
- To enforce Discord's Developer Terms of Service or prevent imminent physical or digital harm to the platform or its users.
06. Data Storage & Security Standards
We implement comprehensive industry-standard technical and organizational security controls to protect your data against unauthorized access, loss, or alteration:
- Encrypted Transport: All communication between Discord, the Kira Bot website, and our backend databases is encrypted in transit via Transport Layer Security (TLS 1.3 / HTTPS).
- Cryptographic Session Tokens: Dashboard sessions use cryptographically signed JWT tokens stored in
SameSite=Lax, HTTP-only, secure cookies with strict CSRF protection. - Database Isolation: Data stores are isolated behind strict firewall configurations with no public direct port exposure. Sensitive credentials (bot tokens, client secrets) are held exclusively in server-side environment variables.
- Access Controls: Only designated core Kira Bot developers have administrative access to the hosting infrastructure.
07. Data Retention & Automated Cleanup
We retain data only as long as necessary to provide active bot services:
- Server Configurations: Maintained for the duration Kira Bot remains installed in your Discord guild. If Kira Bot is removed or kicked from a server, server configurations are flagged for automatic archival and scheduled for deletion after 30 days.
- Audit Logs & Moderation History: Maintained for up to 90 days to provide moderators with infraction logs, after which older records are systematically pruned.
- Web Sessions: Authentication tokens expire automatically after 7 days unless explicitly logged out earlier.
08. User Rights & Data Deletion Requests
Under global privacy frameworks including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), you retain full rights over your data:
- Right to Access: You may request a summary of the data associated with your Discord User ID or server.
- Right to Rectification: You may correct inaccurate or outdated settings directly through the web dashboard or bot commands.
- Right to Erasure (Right to be Forgotten): You may request the total and permanent deletion of all stored data linked to your Discord User ID or guild.
- Join our official Discord Support Server: discord.gg/zFYj4V74tz
- Open a support ticket under the Data & Privacy department.
- Provide your Discord User ID or Server ID and request deletion.
09. Children's Privacy
Kira Bot is designed strictly for users who meet Discord's minimum age requirements. In accordance with Discord's Terms of Service and applicable child safety legislation (including COPPA and GDPR-K), Kira Bot is not intended for individuals under 13 years of age (or the minimum legal age of digital consent in your jurisdiction, such as 16 in certain EU member states).
We do not knowingly collect personal information from children under the applicable age threshold. If we become aware that a user under the legal age has provided personal information, we will take immediate steps to delete that information from our servers.
10. Discord Platform Policy Compliance
Kira Bot operates in full accordance with Discord's developer guidelines and terms:
Kira Bot will never participate in mass unsolicited direct messaging, unauthorized user tracking, token harvesting, or server raiding. Any server utilizing Kira Bot for unlawful activities will have bot access terminated immediately.
11. Contact & Policy Updates
We reserve the right to revise or amend this Privacy Policy at our discretion to reflect technical enhancements, feature releases, or statutory requirements. When material changes are introduced, we will update the "Last Updated" date at the top of this document and broadcast a notification in our official Discord Support Server.
If you have questions, feedback, or concerns regarding this Privacy Policy or our data management practices, please reach out via our official communication channels:
- Official Discord Support Server: https://discord.gg/zFYj4V74tz
- Bug Reports & Feedback Portal: https://kirabot.org/report
- Lead Developer: sleep & Kira Bot Engineering Team